Top Banner
Data Breaches in Payments Systems- Roles and Best Practices for the Public and Private Sector Response Don Rhodes Director Risk Management Policy American Bankers Association Risk Management
12

Data Breaches in Payments Systems- Roles and Best Practices for the Public and Private Sector Response Don Rhodes Director Risk Management Policy American.

Dec 31, 2015

Download

Documents

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Data Breaches in Payments Systems- Roles and Best Practices for the Public and Private Sector Response Don Rhodes Director Risk Management Policy American.

Data Breaches in Payments Systems- Roles and Best Practices for

the Public and Private Sector Response

Don RhodesDirector

Risk Management PolicyAmerican Bankers Association

Risk Management

Page 2: Data Breaches in Payments Systems- Roles and Best Practices for the Public and Private Sector Response Don Rhodes Director Risk Management Policy American.

Risk Management

Agenda

▪ Corporate Account Takeover ▪ Zeus Trojan ▪ Best Practices ▪ ABA Efforts

Risk Management

Page 3: Data Breaches in Payments Systems- Roles and Best Practices for the Public and Private Sector Response Don Rhodes Director Risk Management Policy American.

Risk Management

Spear Phishing

Page 4: Data Breaches in Payments Systems- Roles and Best Practices for the Public and Private Sector Response Don Rhodes Director Risk Management Policy American.

Risk Management

Spear Phishing

Page 5: Data Breaches in Payments Systems- Roles and Best Practices for the Public and Private Sector Response Don Rhodes Director Risk Management Policy American.

Risk Management

Spear Phishing

Page 6: Data Breaches in Payments Systems- Roles and Best Practices for the Public and Private Sector Response Don Rhodes Director Risk Management Policy American.

Risk Management

Banking Trojans in the News

Silver Tail Systems

Page 7: Data Breaches in Payments Systems- Roles and Best Practices for the Public and Private Sector Response Don Rhodes Director Risk Management Policy American.

Risk Management

What Happened in Kentucky?County treasurer had Zeus malware on his PCCriminals stole credentials and logged in to bank accounts from treasurer’s PC

Reconnaissance used to plan theft Mule recruitment pretending to be CareerBuilder Created mules as fictitious employees Mules receive $9700 and sent $9200 to Ukraine via Western Union

More than 25 <$10,000 wire transfers /Total of $415k stolen

Silver Tail Systems

Page 8: Data Breaches in Payments Systems- Roles and Best Practices for the Public and Private Sector Response Don Rhodes Director Risk Management Policy American.

Risk Management

Business Exploit

Page 9: Data Breaches in Payments Systems- Roles and Best Practices for the Public and Private Sector Response Don Rhodes Director Risk Management Policy American.

Risk Management

Best Practices

1. Understand what data is most sensitive to your business

2. Know where this sensitive data resides 3. Understand your risk model 4. Select the appropriate controls based on policy, risk,

and where sensitive data resides 5. Manage security centrally 6. Audit security to constantly improve

http://www.rsa.com/

©2009 RSA Security Inc.

Page 10: Data Breaches in Payments Systems- Roles and Best Practices for the Public and Private Sector Response Don Rhodes Director Risk Management Policy American.

Risk Management

Best Practices

http://www.ftc.gov/infosecurity/

Page 11: Data Breaches in Payments Systems- Roles and Best Practices for the Public and Private Sector Response Don Rhodes Director Risk Management Policy American.

Risk Management

ABA Efforts

▪ National Card Fraud Task Force

▪ Information Security Working Group

▪ Risk Management ForumApril 28-30, Renaissance Vinoy, St. Petersburg, FL

Page 12: Data Breaches in Payments Systems- Roles and Best Practices for the Public and Private Sector Response Don Rhodes Director Risk Management Policy American.

Data Breaches in Payments Systems- Roles and Best Practices for

the Public and Private Sector Response

Don RhodesDirector

Risk Management PolicyAmerican Bankers Association

[email protected]

Risk Management